The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
We have discovered 8,094 live websites that are affected by CVE-2022-4449.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 8,094 live websites (18% of Page Scroll To Id install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 23 versions ( 85% of all versions) |
| 1,476 websites | |
| 990 websites | |
| 604 websites | |
| 493 websites | |
| 404 websites | |
| 281 websites | |
| 262 websites | |
| 261 websites | |
| 206 websites | |
| 205 websites |
| .com | 2,712 websites |
| .de | 622 websites |
| .pl | 434 websites |
| .it | 331 websites |
| .org | 245 websites |
| .cz | 232 websites |
| .ru | 206 websites |
| .nl | 180 websites |
| .com.br | 180 websites |
| .fr | 158 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.com | **,*** | ||
| ******.com | **,*** | ||
| *************.hu | ***,*** | ||
| ***.hu | ***,*** | ||
| ****.*********.com | ***,*** | ||
| *************.com | ***,*** | ||
| ***.********.gov | ***,*** | ||
| ***********.com | ***,*** | ||
| ******.ro | ***,*** | ||
| **********.com | ***,*** |
FAQ